mirror of
https://github.com/caddyserver/caddy.git
synced 2026-08-27 04:07:28 +00:00
Bug fixes and other improvements to TLS functions
Now attempt to staple OCSP even for certs that don't have an existing staple (issue #605). "tls off" short-circuits tls setup function. Now we call getEmail() when setting up an acme.Client that does renewals, rather than making a new account with empty email address. Check certificate expiry every 12 hours, and OCSP every hour.
This commit is contained in:
parent
2dba44327a
commit
1cfd960f3c
7 changed files with 168 additions and 138 deletions
|
|
@ -68,7 +68,7 @@ type TLSConfig struct {
|
|||
Enabled bool // will be set to true if TLS is enabled
|
||||
LetsEncryptEmail string
|
||||
Manual bool // will be set to true if user provides own certs and keys
|
||||
Managed bool // will be set to true if config qualifies for automatic/managed HTTPS
|
||||
Managed bool // will be set to true if config qualifies for implicit automatic/managed HTTPS
|
||||
OnDemand bool // will be set to true if user enables on-demand TLS (obtain certs during handshakes)
|
||||
Ciphers []uint16
|
||||
ProtocolMinVersion uint16
|
||||
|
|
|
|||
|
|
@ -63,15 +63,7 @@ func New(addr string, configs []Config, gracefulTimeout time.Duration) (*Server,
|
|||
var useTLS, useOnDemandTLS bool
|
||||
if len(configs) > 0 {
|
||||
useTLS = configs[0].TLS.Enabled
|
||||
if useTLS {
|
||||
host, _, err := net.SplitHostPort(addr)
|
||||
if err != nil {
|
||||
host = addr
|
||||
}
|
||||
if host == "" && configs[0].TLS.OnDemand {
|
||||
useOnDemandTLS = true
|
||||
}
|
||||
}
|
||||
useOnDemandTLS = configs[0].TLS.OnDemand
|
||||
}
|
||||
|
||||
s := &Server{
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue